Obot 在 v0.23.0 之前的版本中存在一个服务端请求伪造(SSRF)漏洞,该漏洞出现在远程 MCP 服务器注册功能中,允许特权用户指定任意 URL 而无需进行目标地址验证。具有“Power User”或更高级别角色的攻击者可以诱导 Obot 向内部服务和云元数据端点发起请求,并通过读取错误消息中的响应内容,泄露敏感凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| obot-platform | obot | 0 ~ 0.23.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101065 | 9.8 CRITICAL | Obot Quickstart Docker Deployment Unauthenticated Admin Access |
| CVE-2026-101084 | 9.6 CRITICAL | obot before v0.21.1 Authorization Bypass via /mcp-connect |
| CVE-2026-101062 | 8.8 HIGH | Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration |
| CVE-2026-101063 | 5.3 MEDIUM | Obot before v0.23.0 Authentication Bypass via Registry API |
No comments yet